CVE-2003-1350

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
31/12/2003
Last modified:
03/04/2025

Description

List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field delimiter, into the bannerurl field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:list_site_pro:list_site_pro:2.0:*:*:*:*:*:*:*